Vulnerability Description
Skybox Manager Client Application is prone to information disclosure via a username enumeration attack. A local unauthenticated attacker could exploit the flaw to obtain valid usernames, by analyzing error messages upon valid and invalid account login attempts.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Skyboxsecurity | Skybox Manager Client Application | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/101069Third Party AdvisoryVDB Entry
- https://lp.skyboxsecurity.com/rs/440-MPQ-510/images/Skybox_Product_Security_AdviVendor Advisory
- http://www.securityfocus.com/bid/101069Third Party AdvisoryVDB Entry
- https://lp.skyboxsecurity.com/rs/440-MPQ-510/images/Skybox_Product_Security_AdviVendor Advisory
FAQ
What is CVE-2017-14772?
CVE-2017-14772 is a vulnerability with a CVSS score of 3.3 (LOW). Skybox Manager Client Application is prone to information disclosure via a username enumeration attack. A local unauthenticated attacker could exploit the flaw to obtain valid usernames, by analyzing ...
How severe is CVE-2017-14772?
CVE-2017-14772 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14772?
Check the references section above for vendor advisories and patch information. Affected products include: Skyboxsecurity Skybox Manager Client Application.